ACCOUNTING INFORMATION SYSTEM
C A S E A N A LY S I S OF
IN TERN A
L AUDIT
DEFICIEN
CASE BACKGROUND
XYZ COMPANY IS A MEDIUM-SIZED RETAIL BUSINESS THAT HAS BEEN
OPERATING FOR OVER A DECADE. THE CO MPANY OFFERS A WIDE RANGE
OF PRODUCTS, INCLUDING ELECTRONICS, APPAREL, AND H O M E GOODS.
RECENTLY, THE CO MPANY EXPERIENCED A SIGNIFICANT FRAUD INCIDENT
WHERE AN EMPLOYEE WAS CAUGHT STEALING INVENTORY AND
MANIPULATING SALES RECORDS TO CONCEAL THE THEFT.
AS A RESULT OF THIS INCIDENT, THE MANAGEMENT TEAM AT XYZ
CO MPANY HAS REALIZED THE NEED TO EVALUATE THE COMPANY'S INTERNAL
CONTROLS. THEY RECOGNIZE THAT THE CURRENT SYSTEM M AY HAVE
WEAKNESSES THAT COULD ALLOW SIMILAR FRAUDULENT ACTIVITIES TO OCCUR
IN THE FUTURE. MANAGEMENT IS COMMITTED TO IMPROVING THE COMPANY'S
INTERNAL CONTROLS TO PREVENT FUTURE OCCURRENCES OF FRAUD AND TO
PROTECT THE COMPANY'S ASSETS.
CASE BACKGROUND
TO A C H I E V E THIS, M A N A G E M E N T H A S D E C I D E D TO C O N D U C T A C O M P R E H E N S I V E
R E V I E W O F T H E C O M P A N Y ' S I N T E R N A L C O N T R O L S . T H E R E V I E W WILL F O C U S
O N K E Y AREAS, S U C H AS S E G R E G AT I O N O F DUTIES, A U T H O R I Z AT I O N A N D
A P P R O V A L P R O C E SS E S, P H Y S I C A L C O N T R O L S , I N F O R M AT I O N T E C H N O L O G Y
CONTROLS,
R E C O N C I L I AT I O N , D O C U M E N T A T I O N A N D R E C O R D - K E E P I N G , P E R F O R M A N C E
REVIEWS, A N D T R A I N I N G A N D C O M M U N I C AT I O N . T H E U LT I M AT E G O A L O F THIS
R E V IE W IS T O ID E N T IF Y A N Y D E F IC IE N C IE S IN T H E C O M P A N Y ' S IN T E R N A L
C O N T R O L S A N D TO D E V E L O P A P L A N TO A D D R E S S T H E S E DEFICIENCIES.
X Y Z C O M P A N Y IS C O M M I TT E D TO E N S U R I N G T H E INTEGRITY O F ITS F I N A N C I A L
S TAT E M E N T S , P R OT E C T I N G ITS ASSETS, A N D M A I N TA I N I N G T H E TRUST
O F ITS C U S T O M E R S A N D S H A R E H O L D E R S . T H E M A N A G E M E N T T E A M
R E C O G N I Z E S T H AT THIS WILL R E Q U I R E A C O N C E R T E D E F F O RT TO S T R E N G T H E N
T H E C O M P A N Y ' S I N T E R N A L C O N T R O L S A N D TO E N S U R E T H AT T H E Y A R E
FINDINGS
Y O U R T E A M IS TA S K E D TO C O N D U C T A N I N T E R N A L A U D I T TO ASSESS T H E E F F E C T I V E N E S S
O F X Y Z C O M P A N Y ' S I N T E R N A L C O N T R O L S . T H E A U D I T N E E D S TO I D E N T I F Y S E V E R A L
C O N T R O L D E F I C I E N C I E S T H AT C O U L D P O T E N T I A L LY L E A D TO F R A U D A N D F I N A N C I A L LOSS
B A S E D O N T H E ACTIVITIES:
A. SEGREGATION OF DUTIES:
T H E R E IS N O C L E A R S E P A R AT I O N O F D U T I E S B E T W E E N E M P L O Y E E S R E S P O N S I B L E F O R
HA NDLIN G CASH A N D EMPLOYEES RESPONSIBLE FOR RECONCILING CASH
TRANSACTIONS.
T H E S A M E E M P L O Y E E IS R E S P O N S I B L E F O R B O T H INITIATING A N D A P P R O V I N G
P U R C H A S E O R D E R S, W H I C H I N C R E A S E S T H E RISK O F E R R O R S O R F R A U D .
E M P L O Y E E S W I T H A C C E S S TO SENSITIVE F I N A N C I A L I N F O R M AT I O N A L S O H A V E A C C E S S
TO T H E P H Y S I C A L ASSETS T H E Y A R E R E S P O N S I B L E F O R S A F E G U A R D I N G , W H I C H C O U L D
L E A D TO P O T E N T I A L C O N F L I C T S O F INTEREST.
FINDINGS
B. AUTHORIZATION AND APPROVAL PROCESSES:
THERE IS N O F O R M A L PROCESS FOR AU THORIZIN G A N D A P P R O V I N G FINANCIAL
TRANSACTIONS, S U C H AS P U R C H A S E ORDERS OR P AY M E N T REQUESTS.
THE A P P R O VA L PROCESS FOR E M P L O Y E E EXPENSE RE IMB U RSE ME N TS IS N OT CLEARLY
DEFINED, LE ADIN G TO INCONSISTENT A P P R O VA L S A N D POTENTIAL FRAUD.
S O M E E M P LOY E E S H AV E THE AU THORITY TO A P P R O V E TRAN SACTION S B E Y O N D THEIR
AREA O F EXPERTISE OR RESPONSIBILITY, W H I C H INCREASES THE RISK O F ERRORS OR
FRAUD.
FINDINGS
C. PHYSICAL CONTROLS:
T H E R E AR E N O S E C U R I TY C A M E R A S O R O T H E R M O N I T O R I N G D E V I C E S IN T H E
W A R E H O U S E O R S TO R A G E AREAS, W H I C H C O U L D I N C R E A S E T H E RISK O F T H E F T O R
U N A U T H O R I Z E D A C C E SS.
T H E R E IS N O S Y S T E M IN P L A C E TO T R A C K T H E M O V E M E N T O F I N V E N T O R Y O R ASSETS,
M A K I N G IT D I F F I C U LT TO I D E N T I F Y MISSIN G ITEMS.
T H E R E IS N O F O R M A L P R O C E S S F O R R E P O RT I N G A N D I N V E S T I G AT I N G MISSIN G O R
S TO L E N ITEMS.
FINDINGS
D. INFORMATION TECHNOLOGY CONTROLS:
P A S S W O R D S A R E N O T R E G U L A R LY U P D AT E D O R C H A N G E D , I N C R E A S I N G T H E
RISK O F U N A U T H O R I Z E D A C C E S S TO SENSITIVE S Y S T E M S A N D D ATA .
T H E R E IS N O S Y S T E M IN P L A C E F O R M O N I T O R I N G A N D L O G G I N G A C C E S S TO
SENSITIVE D ATA O R S Y S T E M S, M A K I N G IT D I F F I C U LT TO I D E N T I F Y P OT E N T I A L
B R E A C H E S O R MIS U S E.
E M P L O Y E E S A R E A L L O W E D TO U S E THEIR P E R S O N A L D E V I C E S TO A C C E S S
C O M P A N Y S Y S T E M S A N D D ATA , I N C R E A S I N G T H E RISK O F D ATA B R E A C H E S O R
U N A U T H O R I Z E D A C C E SS .
FINDINGS
E. RECONCILIATION:
R E C O N C I L I AT I O N O F B A N K S TAT E M E N T S IS N O T D O N E R E G U LA R LY,
M A K I N G IT D I F F I C U LT TO IDENTIFY ER R OR S OR F R A U D U L E N T ACTIVITY.
T H E R E IS N O F O R M A L P R O C E SS F O R R E C O N C I L I N G P H Y S I C A L I N V E N T O R Y
C O U N T S W I T H R E C O R D E D I N V E N TO R Y, L E A D I N G TO P OT E N T I A L
D I S C R E PA N C I E S.
T H E P R O C E SS F O R R E C O N C I L I N G SALES R E C O R D S W I T H B A N K DEPOSITS
IS N O T C L E A R LY D E F I N E D, L E A D I N G TO P OT E N T I A L ER R OR S OR F R A U D.
FINDINGS
F. D O CU M EN TA TIO N A N D RECO RD - KEEPIN G:
T H E R E IS N O F O R M A L S Y S T E M F O R D O C U M E N T I N G A N D T R A C K I N G A P P R O V A L S
A N D A U T H O R I Z AT I O N S , L E A D I N G TO P OT E N T I A L E R R O R S O R F R A U D .
SO M E E M P L O Y E E S A R E N O T R E Q U IR E D T O M A IN T A IN A C C U R A T E A N D U P - T O -
D A T E R E C O R D S , W H I C H C O U L D L E A D TO E R R O R S O R O M I S S I O N S IN F I N A N C I A L
R E P O RT I N G .
T H E R E IS N O S Y S T E M IN P L A C E F O R A R C H I V I N G A N D S TO R I N G F I N A N C I A L R E C O R D S ,
M A K I N G IT D I F F I C U LT TO RETRIEVE A N D V ER IFY I N F O R M AT I O N .
FINDINGS
G. PERFORMANCE REVIEWS AND MONITORING:
T H E R E IS N O S Y S T E M IN P L A C E F O R R E G U L A R LY M O N I T O R I N G E M P L O Y E E
P E R F O R M A N C E , M A K I N G IT D I F F I C U LT TO I D E N T I F Y P O T E N T I A L ISSUES O R
A R E A S F O R I M P R O V E M E N T.
E M P L O Y E E S A RE N O T P R O V I D E D W I T H R E G U L A R F E E D B A C K O N THEIR
P E R F O R M A N C E O R G O A L S , W H I C H C O U L D L E A D TO D I S E N G A G E M E N T O R
SUBPAR P E R F O R M A N C E .
T H E R E IS N O F O R M A L P R O C E S S F O R C O N D U C T I N G I N T E R N A L A U D I T S O R
ASSESSMENTS OF THE C O M P A N Y ' S INTERNAL CONTROLS.
FINDINGS
H. TRAINING AND COMMUNICATION:
T H E R E IS N O F O R M A L T R A I N I N G P R O G R A M F O R N E W E M P L O Y E E S O N I N T E R N A L
C O N T R O L S OR F R A U D PREVENTION.
SO M E E M P L O Y E E S A R E N O T A W A R E O F T H E C O M P A N Y ' S P O L IC IE S A N D
P R O C E D U R E S F O R H A N D L I N G F I N A N C I A L T R A N S A C T I O N S , L E A D I N G TO P OT E N T I A L
E R R O R S O R F R A U D.
C O M M U N I C AT I O N B E T W E E N D E P A R T M E N T S A N D E M P L O Y E E S IS
I N C O N S I S T E N T, L E A D I N G TO P OT E N T I A L M I S U N D E R S TA N D I N G S O R E R R O R S IN
FINANCIAL
R E P O RT I N G .
R E C O M M E N D AT I O N
A. SEGREGATION OF DUTIES:
I M P L E M E N T A C L E A R S E PA R AT I O N O F DUTIES B E T W E E N E M P L O Y E E S
RESPONSIBLE FOR H A N D LI N G CASH A N D EMPLOYEES RESPONSIBLE FOR
RECONCILING CASH TRANSACTIONS.
ASS IGN D I F F E R E N T E M P L O Y E E S TO INITIATE A N D A P P R O V E P U R C H A S E O R D E R S
TO R E D U C E T HE RISK O F ER R OR S OR F R A U D.
LIMIT A C C E S S TO SENSITIVE F I N A N C I A L I N F O R M AT I O N TO E M P L O Y E E S W H O D O
N O T H A V E A C C E S S TO P H Y S I C A L ASSETS T H E Y A RE R E S P O N S I B L E F O R
SAFEGUARDING.
R E C O M M E N D AT I O N
B. AUTHORIZATION AND APPROVAL PROCESSES:
I M P L E M E N T A F O R M A L PROCESS FOR AUTHORIZING A N D A P P R O V I N G FINANCIAL
T R A N S A C T I O N S , S U C H AS P U R C H A S E O R D E R S OR P A Y M E N T R EQ UESTS.
E S TA B LI S H A C L E A R A N D C O N S I S T E N T A P P R O V A L P R O C E S S F O R E M P L O Y E E
EXPENSE REIMBURSEMENTS.
LIMIT T HE A U T H O R I TY O F E M P L O Y E E S TO A P P R O V E T R A N S A C T I O N S TO THEIR
A R E A O F EXPERTISE OR RESPONSIBILITY.
R E C O M M E N D AT I O N
C. PHYSICAL CONTROLS:
INSTALL SEC UR ITY C A M E R A S OR OT H E R M O N I T O R I N G D E V I C E S IN T H E
W A R E H O U S E OR S TO R A G E A REAS.
I M P L E M E N T A S Y S T E M TO T R A C K T H E M O V E M E N T O F I N V E N T O R Y OR
ASSETS.
E S TA B LI S H A F O R M A L P R O C E S S F O R R E P O RT I N G A N D I N V E S T I G AT I N G M ISSING
OR S TO L E N ITEMS.
R E C O M M E N D AT I O N
D. INFORMATION TECHNOLOGY CONTROLS:
I M P L E M E N T A R E G U L A R P A S S W O R D U P D AT E A N D C H A N G E P OLI C Y.
E S TA B LI S H A S Y S T E M F O R M O N I T O R I N G A N D L O G G I N G A C C E S S TO SENSITIVE
D ATA OR SYST EM S.
P R OHIBI T T HE USE O F P E R S O N A L D E V I C E S TO A C C E S S C O M P A N Y S Y S T E M S A N D
D ATA .
R E C O M M E N D AT I O N
E. RECONCILIATION:
C O N D U C T R E G U L A R R E C O N C I L I AT I O N O F B A N K S TAT E M E N T S TO
IDENTIFY ER R OR S OR F R A U D U L E N T ACTIVITY.
E S TA B LI S H A F O R M A L P R O C E S S F O R R E C O N C I L I N G P H Y S I C A L I N V E N T O R Y
C O U N T S W I T H R E C O R D E D I N V E N TO R Y.
D E F I N E A N D I M P L E M E N T A C L E A R P R O C E S S F O R R E C O N C I L I N G SALES R E C O R D S
W I T H B A N K DEPOSITS.
R E C O M M E N D AT I O N
F. D O CU M EN TA TIO N A N D RECO RD - KEEPIN G:
IMPLEMENT A F O R M A L SYSTEM FOR D O C U M E N T I N G A N D TRACKING APPROVALS
A N D A U T H O R I Z AT I O N S .
R E Q UI R E A LL E M P L O Y E E S TO M A I N TA I N A C C U R AT E A N D U P - TO- D AT E
R E C O R D S. E S TA B LI S H A S Y S T E M F O R A R C H I V I N G A N D S TO R I N G F I N A N C I A L
R E C O R D S.
R E C O M M E N D AT I O N
G. PERFORMANCE REVIEWS AND MONITORING:
I M P L E M E N T A S Y S T E M F O R R E G U L A R LY M O N I T O R I N G E M P L O Y E E P E R F O R M A N C E
A N D I D E N T I F Y I N G P OT E N T I A L ISSUES OR A R E A S F O R I M P R O V E M E N T.
P R O V I D E R E G U L A R F E E D B A C K TO E M P L O Y E E S O N THEIR P E R F O R M A N C E OR
GOALS.
C O N D U C T R E G U L A R I N T E R N A L AU D I TS OR A S S E S S M E N T S O F T H E C O M P A N Y '
S INTERNAL CONTROLS.
R E C O M M E N D AT I O N
H. TRAINING AND COMMUNICATION:
IM PLEM ENT A F O R M A L TRAINING P R O G R A M FOR N E W EMPLOYEES O N INTERNAL
C O N T R O L S OR F R A U D P R E V E N T I O N .
E N S U R E A LL E M P L O Y E E S ARE A W A R E O F T H E C O M P A N Y ' S POLICIES
A N D PROCEDURES FOR H A N D LI N G FINANCIAL TRANSACTIONS.
I M P R O V E C O M M U N I C AT I O N B E T W E E N D E P A R T M E N T S A N D E M P L O Y E E S TO
R E D U C E P OT E N T I A L M I S U N D E R S TA N D I N G S OR ER R OR S IN F I N A N C I A L
R E P O RT I N G .
CONCLUSION
IN S U M M A R Y, A F T E R C O N D U C T I N G A N A U D I T O F X Y Z C O M P A N Y ' S I N T E R N A L
C O N T R O L S , S E V E R A L W E A K N E S S E S W E R E F O U N D T H AT C O U L D L E A D TO F R A U D U L E N T
A C T I V I TY O R F I N A N C I A L LOSS. T H E S E W E A K N E S S E S W E R E F O U N D IN D I F F E R E N T A R E A S
S U C H AS H A N D L I N G C A S H , A P P R O V I N G T R A N S A C T I O N S , P H Y S I C A L A SSET S EC URITY,
I N F O R M AT I O N T E C H N O L O G Y S EC URITY, F I N A N C I A L R E C O R D - K E E P I N G , P E R F O R M A N C E
MONITORING, A N D E M P L O Y E E TRAINING.
TO A D D R E S S T H E S E ISSUES, T H E C O M P A N Y N E E D S TO I M P L E M E N T S PEC IFIC A C T I O N S
F O R E A C H A R E A O F C O N C E R N S U C H AS S E P A R AT I N G T H E D U T I E S O F E M P L O Y E E S
R E S P O N S I B L E F O R H A N D L I N G C A S H , E S TA B L I S H I N G F O R M A L P R O C E S S E S F O R
A P P R O V I N G T R A N S A C T I O N S , I N S TA L L I N G S E C U R I TY C A M E R A S , M O N I T O R I N G A C C E S S
TO SENSITIVE D ATA , R E C O N C I L I N G B A N K S TAT E M E N T S R E G U L A R LY, D O C U M E N T I N G
APPROVALS, M O N I TO R I N G E M P L OY E E P E R F O R M A N C E , A N D PROVIDING E M P L OY E E
TRAINING.
BY IM PLEM EN TIN G TH ESE A CTIO N S, X YZ C O M PA N Y C A N STREN GTH EN ITS
IN TERN A L CONTROLS, REDUCING THE RISK OF FRAUD AND FINANCIALLOSS.
DOING SO WILL
H ELP TH E C O M PA N Y EN SU RE TH E A CC U RA C Y O F ITS FIN A N C IA L STA TEM EN TS,
PROTECT ITS ASSETS, AND MAINTAIN THE TRUST OF ITS CUSTOMERS AND
GROUP M E M B E R S :
ALEGIA, A L F R E D
ATAY, A R I A N N E
CABASAG, THRISHA MARIE
CUYSONA, KRISHA M A E
M A R O N E , C H R I S TY W AY N E
TORRES, J A N A H